SNMP CVE Database

This page lists known Common Vulnerabilities and Exposures (CVEs) related to SNMP. Understanding these vulnerabilities is crucial for effective penetration testing and security assessment.

CVE-2020-7937: Net-SNMP Command Injection
Published: 2020-07-15
Critical

The Net-SNMP agent daemon (snmpd) contains a command injection vulnerability in the AgentX protocol handling. A malicious AgentX client can inject shell commands that will be executed with the privileges of the snmpd process.

Affected Versions: Net-SNMP versions prior to 5.8.1.pre1

CVE-2019-20892: Net-SNMP Denial of Service
Published: 2019-11-22
High

The SNMP protocol implementation in Net-SNMP before 5.8.1.pre1 has a double free that may lead to remote code execution or denial of service via an authenticated user sending crafted packets.

Affected Versions: Net-SNMP versions prior to 5.8.1.pre1

CVE-2018-18066: Net-SNMP Memory Leak
Published: 2018-10-09
Medium

Net-SNMP 5.7.3 through 5.8 has a memory leak in usm_free_usmStateReference via snmp_api.c and snmp_secmod.c when an SNMPv3 GetBulk request is sent.

Affected Versions: Net-SNMP versions 5.7.3 through 5.8

CVE-2015-5621: Net-SNMP Information Disclosure
Published: 2015-07-20
Medium

Net-SNMP 5.7.2.1 and earlier allows remote attackers to obtain sensitive information via a GetBulk request with a large max-repetitions value, which triggers an out-of-bounds read.

Affected Versions: Net-SNMP versions 5.7.2.1 and earlier

CVE-2014-3565: SNMP v3 Authentication Bypass
Published: 2014-09-24
High

SNMP v3 in Cisco IOS and IOS XE does not properly implement the HMAC-SHA-96 authentication method, which makes it easier for remote attackers to obtain read and write access via a brute-force approach to guessing the authentication key.

Affected Versions: Multiple Cisco IOS and IOS XE versions

CVE-2012-2141: Net-SNMP Trap Handling DoS
Published: 2012-05-04
Medium

Net-SNMP 5.7.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted SNMP trap.

Affected Versions: Net-SNMP versions 5.7.1 and earlier

CVE-2008-0960: SNMP Community String Information Disclosure
Published: 2008-02-20
High

The SNMP implementation in Cisco IOS 12.0 through 12.4 allows remote attackers to determine the SNMP community string via crafted SNMP packets that trigger different responses for valid and invalid community strings.

Affected Versions: Cisco IOS 12.0 through 12.4

CVE-2004-0572: SNMP v3 Authentication Bypass
Published: 2004-06-16
Critical

The SNMP v3 implementation in Cisco IOS 12.2 and 12.3 allows remote attackers to bypass authentication and gain read access to the MIB via SNMP packets with modified digest values.

Affected Versions: Cisco IOS 12.2 and 12.3